How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet

0 0

How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet

An attacker exploited a Gnosis Safe wallet on Ethereum, removing about 2,900 rsETH, worth roughly $7.8 million, on Tuesday.

An automated bot known as “yoink” front-ran the attack transaction and extracted the tokens, security firms BlockSec, Blockaid and SlowMist said.

The victim’s wallet was set up to let a helper contract move money for it, an ordinary arrangement for people who automate their trading. The helper was meant to verify that the caller had permission, but SlowMist and BlockSec found the check approved anyone who named the helper itself as the target.

The attacker then dumped around 2,900 rsETH into a trading pool built minutes earlier around a worthless token called Permissionless Attacker Token, leaving the wallet with a receipt worth nothing. Yoink’s bot paid roughly $47,000 to jump the queue and took the tokens, sending 2,882 rsETH to a separate address.

“The root cause was a flawed authorization check in the Multicall contract,” AstraSec said in a post on X. Other security firms agreed the failure was in a component the wallet owner had chosen to trust, not in Safe’s core contracts. Kelp DAO, which issues rsETH, says its contracts are secure and rsETH is fully collateralized.

“We’ve detected potential suspicious activity on an address that received rsETH a few hours ago,” KelpDAO wrote on X. “Out of an abundance of caution, we’ve placed that address under a temporary 24-hour pause. During this window, rsETH cannot move in or out of it.”

Source

Leave A Reply

Your email address will not be published.